Executive brief
HCL BigFix Remote Control is a tool used by IT administrators to remotely manage and troubleshoot computers across an organization. A security configuration error in its web interface could allow an attacker to bypass browser-based security protections. If exploited, this could lead to the loading of unauthorized content or malicious scripts, potentially compromising the integrity of the administrative session.
Technical details
A vulnerability exists in the HCL BigFix Remote Control Server WebUI due to an improperly configured Content Security Policy (CSP). The policy fails to define specific directives without insecure fallbacks, which can lead to Improper Restriction of Rendered UI Layers or Frames (CWE-1021). An attacker with high privileges could potentially exploit this over the network, though it requires user interaction and specific environmental conditions (high complexity). Successful exploitation allows the bypass of intended security restrictions to load unauthorized resources or perform UI redressing/clickjacking attacks. The issue is present in versions 10.1.0.0442 and earlier.
Affected products
- HCL BigFix Remote Control Server WebUI 10.1.0.0442 and earlier
Timeline
- 2026-05-27: disclosed: Initial disclosure by HCL Software
- 2026-05-27: advisory: NVD record published